Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4969

Опубликовано: 20 мая 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

Отчет

Red Hat Product Security has rated this vulnerability as with Moderate severity. Although this flaw may be exploited by an unauthenticated attacker and through the network, the attacker has little to no control over the information leaked. Additionally, the amount of bytes improperly read is low (only one byte is improperly read per attack), which makes this flaw very difficult to exploit to exfiltrate meaningful sensitive data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsoup3Fix deferred
Red Hat Enterprise Linux 6libsoupOut of support scope
Red Hat Enterprise Linux 7libsoupOut of support scope
Red Hat Enterprise Linux 8libsoupOut of support scope
Red Hat Enterprise Linux 9libsoupFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2367552libsoup: Off-by-One Out-of-Bounds Read in find_boundary() in soup-multipart.c

EPSS

Процентиль: 27%
0.00089
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
29 дней назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
nvd
29 дней назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
debian
29 дней назад

A vulnerability was found in the libsoup package. This flaw stems from ...

CVSS3: 6.5
github
28 дней назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

suse-cvrf
14 дней назад

Security update for libsoup

EPSS

Процентиль: 27%
0.00089
Низкий

6.5 Medium

CVSS3